I am getting the same buildup of files in the $SPLUNK_HOME/var/spool/splunk. These are STACH_NEW files. I understand this is because of bug SPL-59578 as referenced in this post : http://splunk-base.splunk.com/answers/64018/files-left-in-splunk_homevarspoolsplunk
I have also referenced this posting: http://splunk-base.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning
and attempted the fixes in both with no success.
My question is there a work around for this problem an is it safe to continue to remove these files from the folder.
Also if I could just move the files to different drive it would be fine.
The current stanzas I have written for these inputs are
Splunk\etc\system\local.inputs.conf
[monitor://$SPLUNK_HOME\var\spool\splunk\...stash_new]
move_policy = sinkhole
disabled = 0
Splunk\etc\system\local.props.conf
[stash_new] NO_BINARY_CHECK=1